Payment fraud is any unauthorized or deceptive transaction. The legitimate account holder did not initiate or authorize it. From your perspective, the sale looks valid at checkout, you fulfill it, and weeks later the real cardholder disputes. You lose the revenue, often the inventory, pay a dispute fee, and take a hit to your processing standing.
Types of payment fraud merchants face
Different fraud vectors need different controls. Match your gateway rules to the categories you actually see, not every merchant faces every type.
Most common
Card-not-present (CNP) fraud
Stolen card numbers used online or by phone without the physical card. Dominates ecommerce and high-risk CNP processing. Defense: AVS, CVV, 3-D Secure, velocity limits. PCI SSC also publishes merchant security guidance for protecting cardholder data at checkout.
Account access
Account takeover (ATO)
Fraudsters access existing accounts via credential stuffing or phishing, then use saved payment methods. Defense: MFA, device fingerprinting, login velocity.
Dispute abuse
Friendly fraud
A real customer buys, receives the product or service, then disputes the charge with their bank. Defense: Clear descriptors, pre-billing alerts, delivery proof.
Triangulation
Triangulation fraud
A fake storefront takes real orders, then pays you with stolen cards and ships to the buyer. You lose product and funds when the cardholder disputes. Defense: Address mismatch checks, reshipping hub scoring.
Returns
Refund fraud
Abuse of return policies: empty boxes, switched merchandise, or digital non-delivery claims. Defense: Serialized tracking, delayed digital refunds.
Identity
Synthetic identity fraud
Fabricated identities built over months, then used for large fraud sweeps. Defense: Identity verification and scoring at onboarding.
Fraud prevention by business model
Select your primary model for the vulnerabilities and gateway rules that matter most in your vertical.
Subscription & continuity
Friendly fraud on forgotten or unrecognized renewals: buyers disputing valid charges instead of canceling.
Recommended controls
- Send pre-charge notifications 3–7 days before billing.
- Match your statement descriptor to your brand and domain.
- Make self-serve cancellation easier than disputing with the bank.
- Use Verifi CDRN and Ethoca alerts to refund before formal chargebacks.
Building a layered fraud prevention stack
No single fraud check catches every attack. Build layers instead: require the billing address and card security code to match (AVS and CVV), ask high-risk shoppers to verify with their bank through 3-D Secure, and watch for suspicious patterns like the same device or IP trying many cards quickly. Score those signals together in real time rather than trusting any one check alone.
- AVS & CVV: confirm the billing address and the 3-digit code on the card. If the code does not match, decline the sale.
- 3-D Secure 2.0: an extra bank login or one-time code for riskier checkouts. When it passes, fraud liability often shifts to the card issuer. See EMVCo's 3-D Secure overview.
- Device & velocity: watch for the same phone or computer using many cards, or a burst of attempts from one IP. Those are classic card testing patterns.
- Risk scoring: combine those signals into a simple decision: accept, review, or decline before you fulfill the order.
Leading high-risk merchants run orders through four sequential gates from click to post-fulfillment:
Gate 1
Pre-transaction filtering
Block blacklisted IPs, Tor exit nodes, flagged email domains, and device fingerprints tied to past chargebacks before authorization runs.
Gate 2
Authorization-time controls
Require AVS and CVV matching, step-up 3-D Secure on elevated scores, and gateway velocity limits during payment capture.
Gate 3
Post-authorization review
Hold mid-to-high risk physical or high-ticket digital orders briefly. Verify billing/shipping alignment and reshipping addresses before release.
Gate 4
Post-fulfillment alerts
Integrate Verifi CDRN and Ethoca Alerts. When a cardholder reports fraud, you often have 24–72 hours to refund and avoid a formal chargeback fee.
How fraud affects high-risk merchants differently
Mainstream aggregators (Stripe, Square, PayPal) calibrate for low-risk retail. When fraud spikes hit nutraceuticals, subscriptions, digital goods, or travel, standard processors often freeze or terminate without warning. That is why high-risk transactions and high-risk industries need underwriting and fraud controls built for elevated dispute norms.
Standard aggregators
Stripe / Square / PayPal
Automated holds often trigger around 0.5%–0.75% dispute rates. Funds can sit in reserve 90–180 days. Termination may lead to MATCH listing for up to five years.
High-risk specialist
Dedicated partner (Zen Payments)
Underwriting calibrated to your vertical, Verifi/Ethoca alert integrations, custom velocity rules, and risk support when activity spikes, not an instant automated shutdown.
Visa historically flagged Early Warning around 0.65% dispute ratio and Standard monitoring near 0.90%; Mastercard ECM begins near 1.50%. Visa now consolidates fraud and dispute monitoring under VAMP.
Merchants stuck with elevated dispute ratios often need a high-chargeback merchant account rather than a retail aggregator, and the right MCC coding from day one.
When fraud gets through
Even with a strong stack, some fraud will land. The response in the first 24–72 hours determines whether you contain damage or trigger a ratio spike.
01
Triage dispute alerts immediately
Act on Verifi CDRN and Ethoca notifications within 24 hours. Refund when representment is unlikely. You avoid the dispute fee and protect your ratio.
02
Isolate the attack pattern
Audit bad orders for shared IP subnets, device fingerprints, card BIN clusters, or reshipping hub addresses, then block what repeats.
03
Tighten gateway rules
Lower velocity thresholds, blacklist identified subnets, or mandate 3-D Secure step-up on matching profiles until the spike passes. Merchants shopping for stronger tooling often look at no-chargeback payment gateway options and high-risk Authorize.net setups.
04
Represent when evidence is strong
For clear friendly fraud, submit delivery proof, IP/device logs, and accepted terms.




